RHSA-2025:12768: Important: redis:6 security update
Important: redis:6 security update
Other sources
Redis is an advanced key-value store. It is often referred to as a data-structure server since keys can contain strings, hashes, lists, sets, and sorted sets. For performance, Redis works with an in-memory data set. You can persist it either by dumping the data set to disk every once in a while, or by appending each command to a log.Security Fix(es): redis: Redis Unauthenticated Denial of Service (CVE-2025-48367) redis: Redis Hyperloglog Out-of-Bounds Write Vulnerability (CVE-2025-32023) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:12768?
The severity of RHSA-2025:12768 is categorized as important.
How do I fix RHSA-2025:12768?
To fix RHSA-2025:12768, upgrade the Redis package to version 6.2.7-1.module+el8.8.0+23374+eaf5d181.5.
Which software versions are affected by RHSA-2025:12768?
RHSA-2025:12768 affects multiple versions of Redis on Red Hat Enterprise Linux, including those for x86_64 and Power LE architectures.
What packages are involved in RHSA-2025:12768?
The affected packages in RHSA-2025:12768 include redis, redis-debuginfo, redis-debugsource, redis-devel, and redis-doc.
Is there a workaround for RHSA-2025:12768?
There are no specific workarounds mentioned for RHSA-2025:12768; the recommended action is to apply the update.